English

Badllama 3: removing safety finetuning from Llama 3 in minutes

Machine Learning 2024-07-02 v1 Artificial Intelligence Computation and Language Cryptography and Security

Abstract

We show that extensive LLM safety fine-tuning is easily subverted when an attacker has access to model weights. We evaluate three state-of-the-art fine-tuning methods-QLoRA, ReFT, and Ortho-and show how algorithmic advances enable constant jailbreaking performance with cuts in FLOPs and optimisation power. We strip safety fine-tuning from Llama 3 8B in one minute and Llama 3 70B in 30 minutes on a single GPU, and sketch ways to reduce this further.

Keywords

Cite

@article{arxiv.2407.01376,
  title  = {Badllama 3: removing safety finetuning from Llama 3 in minutes},
  author = {Dmitrii Volkov},
  journal= {arXiv preprint arXiv:2407.01376},
  year   = {2024}
}